T09 · Insecure Skill Coding Practices
- Location
scripts/index.ts:36- Finding
API Key Exposure Through an Unrestricted Custom Base URL
- Content
View full analysis
Vulnerability Details
File Location:
scripts/index.ts, lines 36–43
Vulnerability Type: Unrestricted credential destination / sensitive information disclosure
Risk Level: MediumVulnerable Code
typescript const DEFAULT_BASE_URL = 'https://hol.org/registry/api/v1'; function getClient(): RegistryBrokerClient { return new RegistryBrokerClient({ baseUrl: process.env.REGISTRY_BROKER_BASE_URL || DEFAULT_BASE_URL, apiKey: process.env.REGISTRY_BROKER_API_KEY, }); }Technical Analysis
The application reads both the API destination and the broker API key from environment variables, then supplies them to the same SDK client.
REGISTRY_BROKER_BASE_URLis accepted without validating its scheme or hostname.Consequently, a party capable of influencing this environment variable can redirect authenticated SDK requests to an arbitrary server. Depending on how the SDK implements authentication, the configured
REGISTRY_BROKER_API_KEYmay be transmitted in an authorization header or another request field to that server.A custom endpoint is not required for the Skill's declared HOL registry functionality. Allowing an unrestricted destination while automatically reusing the production credential therefore exceeds the minimum privileges needed for that functionality.
This audit did not establish that the default
https://hol.org/registry/api/v1endpoint is malicious. The vulnerability arises when the optional base URL is overridden.Attack Path
- An attacker gains the ability to influence the Skill's process environment, deployment configuration,
.envfile, or command runner. - The attacker sets
REGISTRY_BROKER_BASE_URLto an endpoint under their control, such ashttps://attacker.example/api. - A legitimate
REGISTRY_BROKER_API_KEYremains configured in the environment. - The user or agent invokes a CLI operation such as
search_agents,vector_search, `start_conver ...[truncated 1054 chars]
- An attacker gains the ability to influence the Skill's process environment, deployment configuration,
- Remediation
View remediation
Remediation Suggestions
- Remove
REGISTRY_BROKER_BASE_URLsupport if custom API destinations are not essential. - If overrides are required, parse the value with
URLand require thehttps:scheme. - Restrict authenticated requests to an explicit allowlist of trusted hostnames, preferably
hol.organd documented service subdomains only. - Do not automatically attach
REGISTRY_BROKER_API_KEYto non-default origins. Require a separate credential variable for custom endpoints. - Reject URLs containing embedded credentials, unexpected ports, IP-literal hosts, loopback addresses, link-local addresses, or private-network destinations unless explicitly required.
- Display a clear warning or require explicit confirmation before sending chat messages, profiles, or credentials to a non-default endpoint.
- Apply least-privilege scopes and rotation procedures to broker API keys.
- Add automated tests confirming that untrusted schemes and hosts are rejected and that the production key is never attached to custom origins.
Example hardening approach:
typescript const DEFAULT_BASE_URL = new URL('https://hol.org/registry/api/v1'); const configuredUrl = new URL( process.env.REGISTRY_BROKER_BASE_URL || DEFAULT_BASE_URL.href ); if ( configuredUrl.protocol !== 'https:' || configuredUrl.hostname !== 'hol.org' ) { throw new Error('Untrusted Registry Broker base URL'); } const client = new RegistryBrokerClient({ baseUrl: configuredUrl.href, apiKey: process.env.REGISTRY_BROKER_API_KEY, });- Remove
